← Back
CWE-639

2,049 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

JSON object

Loading...

CVEs (2,049)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Piwigo
1Piwigo
Jun 17, 2026
Mar 26, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.
1Harriscomputer
1Ormed Mis
Jun 17, 2026
Mar 25, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thu...Show more
Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.Show less
1Dradisframework
1Dradis
Jun 17, 2026
Mar 16, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
1Grandit
1Grandit
Jun 17, 2026
Mar 2, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified...Show more
GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors.Show less
1Atos
1Unify Openscape Uc Web Client
Jun 17, 2026
Feb 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the...Show more
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and access PINs.Show less
1Hitachienergy
1Asset Suite
Jun 17, 2026
Feb 17, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge...Show more
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.Show less
1Biscom
1Secure File Transfer
Jun 17, 2026
Jan 31, 2020
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authenticated sender because of an error in a file-upload feature. This is fi...Show more
Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authenticated sender because of an error in a file-upload feature. This is fixed in 5.1.1068 and 6.0.1004.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request appro...Show more
An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules.Show less
1Cerberusftp
1Ftp Server
Jun 17, 2026
Jan 14, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling th...Show more
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip and download files even if they do not have permission to view whether the file exists.Show less
1Cththemes
3Citybook
EasybookTownhub
Jun 17, 2026
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
1Ultimatemember
1Ultimate Member
Jun 17, 2026
Jan 13, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos...Show more
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).
1Mi
5Dgnwg03lm Firmware
Mccgq01lm FirmwareRtcgq01lm Firmware+2 more
Jun 17, 2026
Dec 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of se...Show more
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or othe...Show more
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.Show less
1Xtivia
1Web Time And Expense
Jun 17, 2026
Dec 6, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbit...Show more
An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the /Home/GetAttachment function.Show less
1Dasanzhone
1Znid 2426a Firmware
Nov 21, 2024
Nov 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.
1Jenkins
1Google Compute Engine
Jun 17, 2026
Nov 21, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
1Zyxel
12.00(abbx.3)
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized user to access certain pages that require admin privileges.